Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2014:0022-1 Critical Update: Fix for WebYaST Local Access Issue

suse
Calendar Grey January 6, 2014
Scroller Suse
Important revision for WebYaST addresses internal access concern; apply updates through the newest SUSE patch.
An update that fixes one vulnerability is now available

Summary

In the past WebYAST was installed with world readable secret tokens. Although these were modified on the start of the webyast service and so could not be read from remote, it was possible for local attackers on the same machine to read the secrets and so gain local root access via the webyast services. This has been fixed. (CVE-2013-3709) Security Issue reference: * CVE-2013-3709 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - WebYaST 1.2: zypper in -t patch slewyst12-webyast-base-ui-8706 To bring your system up-to-date, use "zypper patch". Package List: - WebYaST 1.2 (noarch) [New Version: 0.2.64]: webyast-base-ui-0.2.64-0.3.1

References

#851116

Cross- CVE-2013-3709

Affected Products:

WebYaST 1.2

https://www.suse.com/security/cve/CVE-2013-3709.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0022-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.